CVE-2026-3911
—CVSS 3.1
2.7 low
EPSS
<1%p26
Published
()
Modified
Description
A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserResource component. By accessing a specific administrative endpoint, this user could improperly retrieve user attributes that were configured to be hidden. This unauthorized information disclosure could expose sensitive user data.
- Vendors
- redhat
- Products
- build of keycloak
- Weakness
- CWE-359
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.